Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ
  procmail¿¡¼­ Swen ¿ú ÇÊÅ͸µ ÀÛ¼ºÀÏ : 2003/09/21 18:55
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 6570
     
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2003.9.21(ÀÏ)

    Swen ¿ú(Win32.Swen@mm.worm, ½ºÀ¢ ¿ú)ÀÌ ±¹³»¿¡µµ µé¾î¿Ô´Ù°í Çϴµ¥, ¾ÆÁ÷ ¹Þ¾Æº¸Áö ¸øÇß½À´Ï´Ù.
    µû¶ó¼­ ¾Æ·¡ ¼³Á¤À» Å×½ºÆ®´Â ¸øÇß½À´Ï´Ù. ¹Ì¸® ÁغñÇÑ´Ù°í ¼ÕÇغ¼ °Íµµ ¾ø°ÚÁÒ?

    Swen¿úÀÌ ¸ÞÀϷθ¸ ÀüÆĵǴ °ÍÀÌ ¾Æ´Ï°í KaZaA P2P ÇÁ·Î±×·¥°ú IRC(mIRC ÀÌ¿ë),
    °øÀ¯µÈ ³×Æ®¿öÅ© Æú´õ¸¦ ÅëÇؼ­µµ ÀüÆĵ˴ϴÙ.

    ´ÙÀ½Àº ¿Ü±¹ÀÇ ÇÑ ´º½º±×·ì¿¡ Æ÷½ºÆõƴø ÇÊÅ͸µ ¼³Á¤ÀÔ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 11ÁÙ)
    /etc/procmailrc ¿¡ Ãß°¡ÇÏ¸é µË´Ï´Ù.
    --------------------------------------------------
    SPAM_LOG = "/var/log/spam.log"

    :0
    * > 140000
    * < 165000
    {
    :0 BD
    * b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv
    $SPAM_LOG
    }
    --------------------------------------------------
    ¸ÞÀÏ Å©±â°¡ 140K~165KÀÌ°í,
    º»¹®¿¡ b3I... °¡ Æ÷ÇÔµÈ °ÍÀº Swen ¿úÀ¸·Î °£ÁÖÇÏ¿© $SPAM_LOG¿¡ ÀúÀåÇصӴϴÙ.
    ¿úÀ» ÀúÀåÇØ µÑ ÇÊ¿ä¾øÀ¸¸é $SPAM_LOG ´ë½Å¿¡ /dev/null·Î.

    Swen ¿úÀÌ Á¦¸ñÀ̳ª ÷ºÎÆÄÀϸíÀÌ ÀÏÁ¤ÇÏÁö ¾Ê±â ¶§¹®¿¡ Àú·± Çü½ÄÀ¸·Î ÇÊÅ͸µÇÕ´Ï´Ù¸¸
    ÇÑ°¡Áö ´Ù¸¥ Ư¡ Áß¿¡ 'subject:'ÀÌ ´ë¹®ÀÚ¶ø´Ï´Ù.
    µû¶ó¼­ ´ÙÀ½°ú °°Àº ÇüÅ·εµ °¡´ÉÇÕ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 5ÁÙ)
    --------------------------------------------------
    SPAM_LOG = "/var/log/spam.log"

    :0 D
    * ^SUBJECT:
    $SPAM_LOG
    --------------------------------------------------

    Swen ¿úÀÇ »ó¼¼ÇÑ Á¤º¸´Â
    http://www.certcc.or.kr/cvirc/Alert/warning/2003/W32_Swen@mm_worm.html
    http://home.ahnlab.com/smart2u/virus_detail_1220.html


    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ / URL : http://coffeenix.net/board_view.php?bd_code=75